Impact
The vulnerability is a type‑confusion flaw (CWE‑843) in Microsoft Office that allows an unauthorized user to execute code locally on a machine. By accessing a resource with an incompatible type, the application can be tricked into running arbitrary code, compromising the confidentiality, integrity, and availability of the affected system.
Affected Systems
Affected products include Microsoft 365 Apps for Enterprise, Microsoft Office 2016, Microsoft Office 2019, Microsoft Office 365 for Mac, Microsoft Office LTSC 2021, Microsoft Office LTSC 2024, Microsoft Office LTSC for Mac 2021, and Microsoft Office LTSC for Mac 2024. The published data does not specify particular versions, but all listed products are considered impacted.
Risk and Exploitability
With a CVSS score of 7.8 the flaw is rated high severity, yet the EPSS score is below 1 percent and it is not listed in CISA's KEV catalog, indicating a low probability of exploitation at present. The likely attack vector is local access or opening a malicious Office file, as no network‑based vector is mentioned. An attacker who succeeds could execute arbitrary code with the privileges of the logged‑in user.
OpenCVE Enrichment